Skip to content

Commit 38b75e9

Browse files
author
Rui Yang
committed
remove python as it introduces CVEs
Signed-off-by: Rui Yang <[email protected]>
1 parent 59a12bb commit 38b75e9

File tree

3 files changed

+497
-71
lines changed

3 files changed

+497
-71
lines changed

Dockerfile

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -48,6 +48,7 @@ RUN apt update && apt install -y --no-install-recommends \
4848
xz-utils \
4949
iproute2 \
5050
&& rm -rf /var/lib/apt/lists/*
51+
RUN apt remove -y python3
5152

5253
COPY --from=builder /assets /opt/resource
5354
RUN ln -s /opt/resource/ecr-login /usr/local/bin/docker-credential-ecr-login

go.mod

Lines changed: 40 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -1,25 +1,54 @@
11
module github.com/concourse/docker-image-resource
22

3-
go 1.14
3+
go 1.20
44

55
require (
6-
github.com/awslabs/amazon-ecr-credential-helper/ecr-login v0.0.0-20220802171026-617dc7abb2ea
6+
github.com/awslabs/amazon-ecr-credential-helper/ecr-login v0.0.0-20230519004202-7f2db5bd753e
77
github.com/cihub/seelog v0.0.0-20160420184328-a98235bd6d92
88
github.com/concourse/retryhttp v0.0.0-20160627222715-dd24ee5a434d
99
github.com/docker/distribution v2.8.2+incompatible
10-
github.com/docker/go-metrics v0.0.1 // indirect
11-
github.com/docker/libtrust v0.0.0-20160708172513-aabc10ec26b7 // indirect
12-
github.com/golang/protobuf v1.4.2 // indirect
13-
github.com/gorilla/context v0.0.0-20160525203319-aed02d124ae4 // indirect
14-
github.com/gorilla/mux v0.0.0-20160718151158-d391bea3118c // indirect
15-
github.com/hashicorp/errwrap v0.0.0-20141028054710-7554cd9344ce // indirect
1610
github.com/hashicorp/go-multierror v0.0.0-20150916205742-d30f09973e19
17-
github.com/niemeyer/pretty v0.0.0-20200227124842-a10e7caefd8e // indirect
1811
github.com/onsi/ginkgo v1.2.1-0.20160722022339-09289bfe14b6
1912
github.com/onsi/gomega v0.0.0-20160718190435-9ed8da19f215
2013
github.com/opencontainers/go-digest v1.0.0
21-
github.com/opencontainers/image-spec v1.0.2 // indirect
2214
github.com/pivotal-golang/clock v0.0.0-20160705185712-da8295109ceb
2315
github.com/pivotal-golang/lager v0.0.0-20160311180000-7639e31ce662
24-
gopkg.in/check.v1 v1.0.0-20200227125254-8fa46927fb4f // indirect
16+
)
17+
18+
require (
19+
github.com/aws/aws-sdk-go-v2 v1.18.0 // indirect
20+
github.com/aws/aws-sdk-go-v2/config v1.18.25 // indirect
21+
github.com/aws/aws-sdk-go-v2/credentials v1.13.24 // indirect
22+
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.13.3 // indirect
23+
github.com/aws/aws-sdk-go-v2/internal/configsources v1.1.33 // indirect
24+
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.4.27 // indirect
25+
github.com/aws/aws-sdk-go-v2/internal/ini v1.3.34 // indirect
26+
github.com/aws/aws-sdk-go-v2/service/ecr v1.18.11 // indirect
27+
github.com/aws/aws-sdk-go-v2/service/ecrpublic v1.16.2 // indirect
28+
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.9.27 // indirect
29+
github.com/aws/aws-sdk-go-v2/service/sso v1.12.10 // indirect
30+
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.14.10 // indirect
31+
github.com/aws/aws-sdk-go-v2/service/sts v1.19.0 // indirect
32+
github.com/aws/smithy-go v1.13.5 // indirect
33+
github.com/beorn7/perks v1.0.1 // indirect
34+
github.com/cespare/xxhash/v2 v2.2.0 // indirect
35+
github.com/docker/docker-credential-helpers v0.7.0 // indirect
36+
github.com/docker/go-metrics v0.0.2-0.20221207153146-523432a393ef // indirect
37+
github.com/docker/libtrust v0.0.0-20160708172513-aabc10ec26b7 // indirect
38+
github.com/golang/protobuf v1.5.3 // indirect
39+
github.com/gorilla/context v0.0.0-20160525203319-aed02d124ae4 // indirect
40+
github.com/gorilla/mux v0.0.0-20160718151158-d391bea3118c // indirect
41+
github.com/hashicorp/errwrap v0.0.0-20141028054710-7554cd9344ce // indirect
42+
github.com/jmespath/go-jmespath v0.4.0 // indirect
43+
github.com/matttproud/golang_protobuf_extensions v1.0.4 // indirect
44+
github.com/mitchellh/go-homedir v1.1.0 // indirect
45+
github.com/opencontainers/image-spec v1.0.2 // indirect
46+
github.com/prometheus/client_golang v1.15.1 // indirect
47+
github.com/prometheus/client_model v0.4.0 // indirect
48+
github.com/prometheus/common v0.44.0 // indirect
49+
github.com/prometheus/procfs v0.9.0 // indirect
50+
github.com/sirupsen/logrus v1.9.2 // indirect
51+
golang.org/x/sys v0.8.0 // indirect
52+
google.golang.org/protobuf v1.30.0 // indirect
53+
gopkg.in/yaml.v2 v2.4.0 // indirect
2554
)

0 commit comments

Comments
 (0)